On 8 August 2023 the UK Electoral Commission disclosed that its systems had been accessed by hostile actors. Reporting traces initial access to August 2021, with the Commission first alerted by a suspicious pattern of login requests in October 2022.
The data covered the names and home addresses of everyone registered to vote between 2014 and 2022 — around 40 million people — including those who had opted out of the open register and the names of registered overseas voters. The Information Commissioner’s Office issued a reprimand, citing basic security failures. In March 2024 the then deputy prime minister told the Commons that Chinese state-linked groups were highly likely to have been responsible.
Fourteen Months, Then Ten More
The two intervals are different failures. Roughly fourteen months of undetected presence is a monitoring problem. The further ten months between detection and public disclosure is a decision.
We have recorded the second interval constantly — 289 days at 26-0721b, two months at 22-0120, four months at 22-0404 — and argues that a notification clock starting at a determination the notifying body controls is not a clock. Here the affected population is the electorate, which cannot be individually notified at all, so the disclosure date is the only moment any of those 40 million people had.
The Opt-Out Is The Part That Stings
The register exists in two forms, and a person who does not want their address publicly available can ask to be excluded from the open one. That is the single lever available to a member of the public who cares about this.
Those people were in the breach. The exposure included precisely the records of those who had taken the one action the system offered them, which is the sharpest version of an argument this desk makes at 22-0922 and 26-0730: a system that collects by law and offers privacy as a preference has made that preference conditional on its own security.
What This Data Is Good For
Names and addresses are not credentials and cannot be used to take money. The corpus is careful not to inflate that.
What a national register provides is coverage — a way to resolve a person to a place at national scale, and to cross-reference other holdings against a reliable spine. The desk records the same property at 26-0715 for telecom metadata. Attribution here is the UK government’s, reported, and this file does not present it as established; but a state-linked actor taking an electoral register is not taking it for fraud.
Compiled from contemporaneous reporting, the Commission’s own disclosure and the ICO’s reprimand, listed below. The attribution to Chinese state-linked groups is the UK government’s statement of March 2024, reported as a "highly likely" assessment; this desk does not present attribution as established fact. Graded high on the timeline and scope. Corrections: corrections@forensicpost.com.